AI is quietly making old-school scams work a lot better
A fake QR code, a chatbot that beat human con artists at building trust, and a state's fraud losses doubling — three data points pointing the same way.
What happened: Three separate reports point to the same trend. In the UK, QR-code scams ('quishing') are up roughly 700% in four years, with criminals sticking fake codes on parking meters to steal card details and set up secret subscriptions. In a university study, an AI chatbot posing as a romantic or investment contact outperformed human scammers: 46% of participants installed an app it recommended, versus 18% for a human, and people said they trusted the bot more. In Idaho, fraud losses to seniors doubled in a year, hitting $37.4 million, with officials citing AI-generated voices and more convincing fake messages.
Why it matters: Scams built on personal connection, like 'pig butchering' romance-investment schemes, used to require scammers to spend weeks manually chatting with a target. The study suggests AI can now do that relationship-building at scale, cheaply, and more convincingly than a person. Combined with QR codes slipping past spam filters and email security, that gives criminals more tools to reach more victims with less effort and fewer telltale mistakes.
How it works, plainly: QR codes hide the real destination of a link, so people scan first and only find out where they landed after entering payment details. Chatbots succeed for a similar reason: they never get tired, instantly recall personal details a victim shared earlier, and keep the conversation going in a way exhausted or distracted human scammers can't match consistently, researchers found.
The rollout: Experts recommend using your phone's built-in camera to scan QR codes rather than a downloaded scanner app, and treating urgency, secrecy, or requests to move money into crypto or gift cards as red flags regardless of who or what is asking. Idaho's finance department is running free fraud-prevention sessions for seniors in six cities this September, and researchers say platforms and regulators will need better tools to detect AI impersonation before it reaches victims.
